Unauthenticated Access Vulnerability in Oracle E-Business Suite Component
CVE-2024-21029
6.1MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 16 April 2024
Summary
This vulnerability in Oracle's Complex Maintenance, Repair, and Overhaul component of the E-Business Suite allows unauthenticated attackers with network access via HTTP to exploit the system. Successful exploitation hinges on the interaction of a third party, not the attacker. This could lead to unauthorized updates, insertions, or deletions of data, as well as unauthorized read access to certain data within Oracle Complex Maintenance, Repair, and Overhaul. Attackers could potentially affect other interconnected products, broadening the impact of the vulnerability beyond the initial target.
Affected Version(s)
Complex Maintenance, Repair, and Overhaul 12.2.3 <= 12.2.13
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published